Path Traversal Vulnerability in ZeroClaw by ZeroClaw Labs
CVE-2026-101885
8.5HIGH
What is CVE-2026-101885?
ZeroClaw versions before 0.8.5 feature a path traversal vulnerability stemming from improper validation of the wasm_path manifest field during plugin installation. This flaw allows attackers to induce users into installing malicious plugins that can write arbitrary files to unintended system paths, including sensitive shell startup files, thus potentially enabling remote code execution.
Affected Version(s)
ZeroClaw 0 < 0.8.5
